Secure Identity Notification via Certificate Hashing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional communication protocols in communications networks are insecure, allowing eavesdropping and monitoring of user or device identities, making it difficult to establish secure connections without revealing identities to other devices or users.

Innovation Solution

A method involving obtaining a certificate associated with an electronic device, generating a hash of the certificate, and sending a communication including the hash to the network, excluding identity information, while using multicast or secure channels for transmission, and securely identifying the sending device by comparing the received hash with stored hashes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional communication protocols are used to communicate identity information, then devices can establish communication links, but identity information becomes vulnerable to eavesdropping and monitoring

Engineering Contradiction:
Improvesecurity of identity communicationVSAvoideavesdropping and monitoring of identity
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the identity information from the communication data by using hash functions to generate a hash value of the identity. Only the hash value is transmitted over the network, while the actual identity information remains stored locally on the device. This extraction principle resolves the contradiction by removing the vulnerable identity data from the communication channel while preserving the ability to identify devices through their hash values.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a hash value as an intermediary between the actual identity information and the communication process. The hash value serves as a mediator that allows device identification without exposing the underlying identity data. This intermediary resolves the contradiction by enabling communication functionality while blocking direct access to sensitive identity information.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If identity information is excluded from communications to enhance security, then eavesdropping is prevented, but device identification becomes more difficult

Engineering Contradiction:
Improvesecurity of identity communicationVSAvoiddevice identification
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent creates a copy of the identity information in the form of a hash value. This hash copy contains sufficient information to uniquely identify the device and enable communication protocols to function, while the original identity information remains protected locally. The copying principle resolves the contradiction by providing an alternative representation that maintains identification capability without exposing sensitive data.

Inventive Principle:
Principle #26Copying

Data Source

PatentEP2605178B1Method and device for secure notification of identity
Publication Date: 2018.10.17 BLACKBERRY LTD
  • EP2605178B1 patent drawingFigure 1
  • EP2605178B1 patent drawingFigure 2
  • EP2605178B1 patent drawingFigure 3

AI summary

A system, methods and devices for the secure notification of an identity in a communications network. The methods include sending or receiving a communication including a hash of a certificate of a device to notify or detect the presence of the device in a network. Each certificate is associated with an identity which is excluded from the communication of the hash of the certificate. The received hash is compared to hashes of certificates stored in an electronic device to determine an identity. The identity may represent an electronic device or a user of the electronic device.